d86d6df147
Panel: Gróa + Regin returned zero (adapter/route-map/error-map faithful);
Hulda flagged two source-confirmed open-world-presenter crash holes — the same
class the slice-4 bug-hunt found in the agents presenters. Both fixed:
- `_format_whoami` scopes (`cli.py`): `', '.join(me.get('scopes', []))` crashes on
a present-null `scopes` (`.get(k, [])` returns None, not the default) or a
non-string element. Now `', '.join(str(s) for s in (me.get('scopes') or []))` —
matching the `allowed_roles` hardening on the same function. The contract names
`_format_whoami` as the degrade-not-crash exemplar (contract:144-146); the cited
exemplar had an un-hardened line.
- `_characters_probe` model items (`cli.py`): the slice-5 `or []` guarded the
list-level null but not each entry — `[None]` / `["x"]` / `[{"name":123}]` would
raise. Now guards each item is a dict and str-coerces `name` (element-level
completion of the list-level guard).
Hulda #3 (live-smoke not in the reviewed file set) → accept: the smoke WAS run and
is recorded in deab762 + coverage-map (artifact-only review couldn't see it).
Added CLI tests for both hardened paths (present-null/non-string scopes; malformed
model items). Suite 485 green; ruff clean; live smoke re-run clean (identical
happy-path output). Patch bump 0.21.16 → 0.21.17.
98 lines
4.3 KiB
TOML
98 lines
4.3 KiB
TOML
[build-system]
|
|
requires = ["hatchling"]
|
|
build-backend = "hatchling.build"
|
|
|
|
[project]
|
|
name = "ratatoskr"
|
|
version = "0.21.17"
|
|
description = "Worldtree Conversation API debug console (web + headless CLI) — multi-pane observability"
|
|
readme = "README.md"
|
|
requires-python = ">=3.12"
|
|
license = { file = "LICENSE" }
|
|
authors = [{ name = "Vuong Hoang" }]
|
|
keywords = ["worldtree", "debug", "sse", "web", "observability"]
|
|
|
|
# Network + SSE consumer.
|
|
# See docs/design-brief.md §3 (httpx-sse).
|
|
dependencies = [
|
|
"httpx>=0.27",
|
|
"httpx-sse>=0.4", # #20 slice-7 teardown drops this once the SDK owns SSE parsing
|
|
"worldtree-sdk==1.0.0", # #20 cutover: the consumer client layer (gitea PyPI); slices retire the hand-rolled wrappers behind ratatoskr.wt
|
|
]
|
|
|
|
[project.optional-dependencies]
|
|
web = [
|
|
"starlette>=0.40",
|
|
"uvicorn[standard]>=0.30",
|
|
]
|
|
# Tier-3 Bifrost consumer: the durable memory.* + affect.* persistence
|
|
# provider Worldtree writes into. Opt-in extra — distinct deployment surface
|
|
# from the debug TUI. Recipe: bifrost/docs/implementing-a-consumer.md.
|
|
provider = [
|
|
"ratatoskr[web]", # reuse the starlette + uvicorn ASGI stack
|
|
"bifrost==1.1.4", # consumer engines + library. 1.1.4 = hasattr-gate backstop for the maintenance verbs (mark_superseded/mark_invalid/patch_many/delete_many/upsert_edges/get_edges_for → unimplemented verb degrades to unsupported_capability 400, never AttributeError/500/retry-storm; we surfaced it via WT #364) + 1.1.3 scan/cursor conformance harness + 1.1.2 frozen-v0.6 fix. 1.1.1 = frozen-wire serialization fix (ADR-0008): additive capability fields are gated on the NEGOTIATED wire, so a v0.6-negotiated describe_store handshake stays v0.6-clean. 1.1.0 leaked the v0.7-additive `sortable_chunk_fields` into v0.6 StoreCapabilities → a strict v0.6 client (additionalProperties:false) rejects our server's handshake. Wire schemas + pins UNCHANGED (serialization-correctness only); our v0.7 handshake with Worldtree b47 is unaffected. (1.1.0 = wire v0.7 additive: memory.scan sort + sortable_chunk_fields; 1.0.0 = first STABLE, wire v0.6 FROZEN; 0.8.0/v0.6 scope_all/scope_any #11; 0.7.0/v0.5 agent_self)
|
|
"jsonschema>=4", # bifrost runtime dep — envelope validation
|
|
"sqlite-vec>=0.1.6", # vector index for the memory plane (vec0 virtual table)
|
|
]
|
|
dev = [
|
|
"pytest>=8",
|
|
"pytest-asyncio>=0.24",
|
|
"respx>=0.21", # httpx mocking for SSE-recorded snapshot tests
|
|
"ruff>=0.6",
|
|
"mypy>=1.11",
|
|
"pyyaml>=6", # used by docs/contracts/contract_parser.py and scripts/contract_drift_check.py
|
|
"ratatoskr[web]", # web extras included in dev so test_web_* can import starlette
|
|
]
|
|
|
|
[project.scripts]
|
|
ratatoskr = "ratatoskr.cli:main"
|
|
ratatoskr-web = "ratatoskr.web.entrypoint:main"
|
|
ratatoskr-provider = "ratatoskr.provider.serve:main"
|
|
ratatoskr-memory-provider = "ratatoskr.provider.serve_memory:main"
|
|
ratatoskr-combined-provider = "ratatoskr.provider.serve_combined:main"
|
|
|
|
[project.urls]
|
|
Repository = "https://gitea.phasefinal.com/vh/ratatoskr"
|
|
"Design Brief" = "https://gitea.phasefinal.com/vh/brokkr-smithy/src/branch/main/docs/ratatoskr-design-brief.md"
|
|
|
|
# Worldtree spec pin — see docs/SPEC-PIN.md for the full bump procedure.
|
|
# Ratatoskr is built against Worldtree at this commit; the vendored
|
|
# spec snapshot in docs/ reflects that SHA.
|
|
[tool.ratatoskr.spec-pin]
|
|
worldtree-spec-rev = "c9e59ec"
|
|
worldtree-version = "v1.0.0b22"
|
|
pinned-on = "2026-07-06"
|
|
|
|
# Bifrost lives on the auth-gated gitea PyPI index (not public PyPI).
|
|
# uv reads the credential from UV_INDEX_GITEA_USERNAME / _PASSWORD or ~/.netrc.
|
|
[[tool.uv.index]]
|
|
name = "gitea"
|
|
url = "https://gitea.phasefinal.com/api/packages/vh/pypi/simple/"
|
|
|
|
[tool.uv.sources]
|
|
bifrost = { index = "gitea" }
|
|
worldtree-sdk = { index = "gitea" }
|
|
|
|
[tool.hatch.build.targets.wheel]
|
|
packages = ["src/ratatoskr"]
|
|
|
|
# Issue #16: ship the web companion's static HTML in the wheel so
|
|
# importlib.resources can locate it post-install.
|
|
[tool.hatch.build.targets.wheel.force-include]
|
|
"src/ratatoskr/web/static" = "ratatoskr/web/static"
|
|
|
|
[tool.pytest.ini_options]
|
|
asyncio_mode = "auto"
|
|
testpaths = ["tests"]
|
|
|
|
[tool.ruff]
|
|
line-length = 100
|
|
target-version = "py312"
|
|
|
|
[tool.ruff.lint]
|
|
select = ["E", "F", "I", "B", "UP", "RUF"]
|
|
|
|
[tool.mypy]
|
|
python_version = "3.12"
|
|
strict = true
|